Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how Monitorix ("Monitorix", "we", "us"), a website and server monitoring service operated by CDX and available at https://monitorix.net, collects, uses, shares and protects information in connection with your use of the Monitorix website, dashboard, API and monitoring agent (together, the "Service"). By creating an account or using the Service you agree to this Policy.

1. Who this Policy applies to

This Policy applies to the account holders and users of Monitorix. If you install the Monitorix agent on a server, this Policy also covers the operational data that agent sends to us. Content you choose to monitor (for example third-party websites) is processed on your instruction and under your responsibility.

2. Information we collect

2.1 Account information

When you register we collect your first and last name, email address and, optionally, your phone number. Your password is stored only as a secure one-way hash — we never store it in readable form. We also record your email-verification status and your account and interface preferences.

2.2 Billing information

When you purchase a paid plan we create orders and invoices that record the plan, amount, currency, gateway used, transaction identifier, payment status and renewal status. We do not store your full payment-card number or CVV on our servers. Card payments are processed by third-party payment providers (see Section 6). Where a provider returns a reusable payment token, we may store only a token together with the card's last four digits and expiry month/year in order to process renewals.

2.3 Monitoring configuration you provide

To run checks for you we store the targets and parameters you configure — for example website URLs, hostnames, domain names, IP addresses, ports, DNS records, keywords and expected responses — and the alert settings you define (recipient email addresses and, if you enable them, Slack or webhook endpoints).

2.4 Data collected by the monitoring agent

If you install our optional agent on a server, the agent collects and sends us operational telemetry about that server so we can monitor it and show it in your dashboard. This may include:

  • the server's hostname, local IP address and public (egress) IP address, geographic region and operating-system/control-panel type;
  • resource metrics: CPU usage and load, memory and swap usage, disk usage and I/O, network traffic and connection counts, and process counts;
  • the list of system services (for example the service name, running state and per-service CPU usage) so you can choose which to monitor;
  • the detected firewall type and, when you request it, the firewall's active rule listing;
  • when you request it, a snapshot of the server's local status page (for example Apache mod_status or nginx stub_status), which the agent reads from the server itself and relays to us.

To determine the server's public IP, the agent contacts one or more public IP-lookup services (such as api.ipify.org, ifconfig.me and icanhazip.com). The agent only performs firewall changes, service restarts or status fetches that you have explicitly enabled or requested from your dashboard.

2.5 Technical and usage data

Like most web services, our servers automatically record standard technical data such as IP addresses, browser type and request logs, and we use session cookies (including an optional "remember me" cookie) to keep you signed in.

3. How we use information

  • to provide, operate and maintain the Service and your dashboard;
  • to perform the monitoring checks you configure and to store their results and history;
  • to send you operational alerts and notifications (for example when a monitored target goes down or recovers, or an SSL certificate or domain is about to expire);
  • to process payments, manage subscriptions and issue invoices;
  • to secure the Service, prevent abuse and troubleshoot problems;
  • to communicate with you about your account, security and service changes;
  • to comply with legal obligations.

4. Cookies

We use strictly necessary cookies to authenticate your session and, if you choose, to keep you signed in. We do not use advertising cookies, and Monitorix does not run third-party advertising or behavioural-tracking analytics on the dashboard.

5. Communications and notifications

We send transactional and operational emails using our email provider. If you configure additional alert channels, alert content is sent to the destinations you specify — extra recipient email addresses, a Slack incoming-webhook URL, or a generic webhook URL. You control these destinations and can change or remove them at any time.

6. Third-party service providers

We share information with a limited set of processors strictly to operate the Service:

  • Payment providers — Stripe, PayPal, Mollie and PayPlus process card and payment-account data directly. Their handling of your payment data is governed by their own privacy policies.
  • Email delivery — we send email through an email provider, which may include Google's Gmail API where configured.
  • Public IP-lookup services — contacted by the agent from your server to determine its public IP (see Section 2.4).
  • Hosting and infrastructure — the providers that host the Monitorix service.

We do not sell your personal information, and we do not share it for third-party advertising.

7. The agent and your servers

The agent is installed by you, on servers you own or are authorized to manage, using an installation token issued to your account. It runs with the privileges you grant it on your server. All potentially sensitive actions — enabling automatic service restarts, managing the firewall, blocking or unblocking IP addresses, or fetching the server-status page — are performed only when you enable or request them from your dashboard. You remain responsible for the servers on which you install the agent.

8. Data retention

We retain your account and configuration data for as long as your account is active. Monitoring metrics, check results and event history are retained to provide history and reporting within the Service. When you delete a monitor, server or your account, the associated data is removed or scheduled for removal, subject to backups and any retention we are legally required to keep. You may request deletion of your data as described in Section 10.

9. Security

We apply reasonable technical and organisational measures to protect your data, including hashing of passwords and agent/API keys, encryption of stored payment-gateway credentials, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights

Subject to applicable law, including the Israeli Protection of Privacy Law and, where relevant, the EU/UK GDPR, you may request to access, correct, export or delete your personal data, and object to or restrict certain processing. You can update most account information directly in your dashboard, or contact us using the details in Section 13. We will respond within the time required by applicable law.

11. International transfers

Monitorix is operated from Israel, and your data — and data collected by the agent — may be processed in Israel and in other countries where we or our processors operate. Where required, we rely on appropriate safeguards for such transfers.

12. Children

The Service is intended for business use and is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use the Service.

13. Contact

For any privacy question or request, contact us at [email protected].

14. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after a change means you accept the updated Policy.